Updated Red Hat Enterprise MRG Messaging and Grid packages that fix onesecurity issue and several bugs are now available for Red Hat EnterpriseLinux 4.

The Red Hat Security Response Team has rated this update as havingimportant security impact. A Common Vulnerability Scoring System (CVSS)base score, which gives a detailed severity rating, is available from theCVE link in the References section.

The Management Console Installation Guide for Red Hat Enterprise MRG 1.3instructed administrators to configure Condor to allow the MRG ManagementConsole (cumin) to submit jobs on behalf of a user. This configurationfacilitated a trust relationship between cumin and the Condor QMF plug-ins;however, there was inadequate access control on the trusted channel,allowing anyone able to publish to a broker to submit jobs to run as anyother user (except root, as Condor does not run jobs as root).(CVE-2010-4179)

All Red Hat Enterprise MRG users are advised to upgrade to these updatedpackages, which correct this issue and the issues noted in the Red HatEnterprise MRG 1.3 Technical Notes. After installing the updated packages,Condor must be restarted for the update to take effect.

4. Solution:

Before applying this update, make sure all previously-released erratarelevant to your system have been applied.